CTEM Engineer
About Courser
Courser accelerates the growth of IT service provider companies. We forge dynamic partnerships, leveraging our values of Teamwork, Service, Growth-Mindedness, Trust, and Innovation to deliver impactful solutions and phenomenal customer experiences. If you thrive in a fast-paced IT environment, join our rapidly expanding team and contribute to our ongoing success.
Continuous Threat Event Monitoring (CTEM) Engineer
The CTEM Engineer leads the continuous identification, validation, prioritization, and remediation of security exposures across managed environments. This role owns the CTEM platform and vulnerability management lifecycle, ensuring threats are accurately assessed and remediated according to risk, business impact, and contractual service commitments.
The CTEM Engineer collaborates with MSP partners, security operations, and technical teams to coordinate remediation activities, monitor program performance, and reduce organizational cyber risk. Key responsibilities include exposure monitoring, vulnerability validation, remediation oversight, stakeholder communication, and maintaining accountability for timely and effective resolution of identified risks. This position plays a critical role in strengthening security posture, improving operational resilience, and driving measurable risk reduction outcomes.
Key Responsibilities:
• Continuously monitor and assess vulnerabilities, exposures, and security risks across managed environments using the CTEM platform and associated security monitoring tools.
• Validate vulnerability detections and threat exposures to eliminate false positives and ensure remediation efforts focus on verified risk.
• Respond to critical and high-risk vulnerability findings by coordinating timely investigation, escalation, and remediation activities.
• Prioritize remediation efforts based on risk, exploitability, business impact, and service-level commitments.
• Partner with MSP engineers, internal technical teams, and security stakeholders to drive vulnerabilities through the remediation lifecycle to closure.
• Track remediation progress and ensure vulnerabilities are resolved within established SLAs and customer commitments.
• Conduct operational analysis of CTEM processes, workflows, and remediation outcomes to identify bottlenecks and opportunities for continuous improvement.
• Perform routine platform administration, including configuration management, policy updates, integrations, and system maintenance.
• Maintain detailed documentation of vulnerability investigations, remediation activities, exceptions, and customer communications.
• Develop and maintain reporting dashboards and metrics that provide visibility into exposure trends, remediation performance, SLA compliance, and overall risk posture.
• Support security architecture and technology improvement initiatives by identifying recurring exposure patterns and recommending long-term corrective actions.
• Document lessons learned from vulnerability and remediation activities and implement preventative measures to reduce future risk.
• Develop and maintain automation, scripting, and workflow enhancements that improve operational efficiency and accelerate remediation efforts.
• Continuously improve CTEM monitoring, detection, prioritization, and reporting capabilities to enhance proactive risk management.
• Build and maintain effective working relationships with MSP partners and internal stakeholders to ensure consistent and timely remediation outcomes.
• Provide regular status updates and executive-ready reporting on vulnerability management performance, exposure reduction efforts, and program effectiveness.
Key Qualifications:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred.
• 1-3 years of experience in vulnerability management, security operations, exposure management, or a related cybersecurity discipline.
• Strong understanding of vulnerability management methodologies, risk assessment frameworks, and remediation best practices.
• Experience working with vulnerability management and security monitoring platforms such as Rootshell, Qualys, Nessus, Microsoft Defender, SentinelOne, and Huntress.
• Knowledge of vulnerability scoring and prioritization models, including CVSS, KEV, and risk-based remediation approaches.
• Solid understanding of network and security fundamentals, including TCP/IP, DNS, VPNs, firewalls, authentication protocols, and endpoint security controls.
• Familiarity with operating system administration and endpoint management across Windows, macOS, and Linux environments.
• Working knowledge of cloud security concepts and platforms, including Microsoft Azure, AWS, and Google Cloud Platform (GCP).
• Experience coordinating vulnerability remediation efforts across technical teams, MSPs, or third-party service providers.
• Understanding of incident management, problem management, change management, and service delivery processes.
• Proficiency in scripting or automation technologies such as PowerShell, Python, or Bash.
• Experience developing reports, dashboards, and metrics to measure vulnerability management and remediation performance.
• Strong analytical, troubleshooting, and risk assessment skills with the ability to prioritize competing remediation activities.
• Excellent written and verbal communication skills, including the ability to communicate technical risks to both technical and non-technical stakeholders.
• Strong organizational skills with the ability to manage multiple remediation efforts while maintaining SLA compliance.
• Relevant industry certifications such as Security+, CySA+, SC-200, SC-300, CISSP, GSEC, or comparable certifications are preferred.
Preferred Experience:
• Experience working within a Managed Service Provider (MSP) environment.
• Familiarity with Continuous Threat Exposure Management (CTEM) frameworks and vulnerability lifecycle management.
• Knowledge of security frameworks such as NIST CSF, CIS Controls, NIST 800-53, or ISO 27001.
• Experience integrating vulnerability management platforms with ticketing, reporting, and automation systems.
• Understanding of exposure validation, attack path analysis, and risk-based prioritization techniques.
• Experience leveraging automation to improve remediation workflows and operational efficiency.
Why you’ll love working here
At Courser, we prioritize the personal and professional development of our employees. We offer best-in-class training, mentorship, and clear self-promotion paths to help you grow. We foster a culture of innovation and encourage challenging the status quo. With teams located across the country, we leverage a wealth of knowledge and a collaborative spirit, eager to share and grow together.
Benefit Highlights
• Competitive benefits package, including medical, dental, vision, and life insurance
• 401(k) company match
• Flexible vacation time*
• Paid sick time
• 10 Holidays including your Birthday and a Floating Holiday!
• Healthy Lifestyle reimbursement
• Membership Subsidy
• 40 Hours for Volunteer Time
• Paid parental leave
• Reimbursement for ongoing certifications
*Flexible vacation time after completing one full year of employment. For the first year of employment,
full-time team members are provided 10 vacation days.
Physical Demands and ADA Requirements
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.
• This is a largely sedentary role. The employee is frequently required to sit/stand for long periods and work on a computer.
• The employee must be able to verbally communicate effectively with clients, employees and management to address questions and resolve issues. This involves talking, hearing, and understanding.
• This position requires the regular use of a laptop computer and other office equipment. The employee must be able to operate a keyboard and other devices for extended periods.
• The employee may be required to occasionally lift or move up to 10 pounds.
• Specific vision abilities required by this job include close vision, distance vision, and the ability to adjust focus.
Americans with Disabilities Act (ADA) Statement
Our company complies with the ADA and provides reasonable accommodations to qualified individuals with disabilities in all aspects of employment, including the application process, interviewing, and job performance. If you need a reasonable accommodation to perform the essential functions of the job, please contact us.
Equal Opportunity Employer
Courser is an Equal Opportunity Employer. We support diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, gender, gender identity, genetic information, national origin, citizenship status, marital status, age, physical or mental disability, caregiver status, veteran status, uniformed service member status or any other category protected by applicable federal, state, or local laws.